<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Stephen_McCloskey's WebLog</title><link>http://blogs.msdn.com/stephen_mccloskey/default.aspx</link><description>Tripping through the managed landscape.</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>More on password sniffing</title><link>http://blogs.msdn.com/stephen_mccloskey/archive/2004/03/09/86868.aspx</link><pubDate>Tue, 09 Mar 2004 22:41:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:86868</guid><dc:creator>Stephen_McCloskey</dc:creator><slash:comments>9</slash:comments><comments>http://blogs.msdn.com/stephen_mccloskey/comments/86868.aspx</comments><wfw:commentRss>http://blogs.msdn.com/stephen_mccloskey/commentrss.aspx?PostID=86868</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Here are some articles about password sniffing and real-world systems.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Documented accounts of successful password sniff attacks do actually exist.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;(I&amp;#8217;m not trying to pick on the &lt;?xml:namespace prefix = st1 ns = "urn:schemas-microsoft-com:office:smarttags" /&gt;&lt;st1:City w:st="on"&gt;OSS&lt;/st1:City&gt; folks when it comes to poor password handling, but the two most recent incidents were connected with &lt;st1:City w:st="on"&gt;&lt;st1:place w:st="on"&gt;OSS&lt;/st1:place&gt;&lt;/st1:City&gt; systems.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In reality, &lt;st1:City w:st="on"&gt;&lt;st1:place w:st="on"&gt;OSS&lt;/st1:place&gt;&lt;/st1:City&gt; and non-OSS systems are equally vulnerable to password sniffing attacks.)&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Debian had a few of its servers compromised a few months back.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It looks like the attack started with a simple sniffed password. See &lt;A href="http://kerneltrap.org/node/view/1717"&gt;this&lt;/A&gt; and &lt;A href="http://slashdot.org/article.pl?sid=03/11/28/050232&amp;amp;mode=thread"&gt;this&lt;/A&gt;.&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;The FSF Savannah project had the same attack successfully performed on them.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The article does not mention the password sniffing part, but does say that the attack was identical to the Debian attack.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Does anyone know if a sniffed password was also used in this attack? See &lt;A href="http://linuxtoday.com/news_story.php3?ltsn=2003-12-04-014-26-SC-SV&amp;amp;tbovrmode=3"&gt;this&lt;/A&gt;.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;A href="http://www.cert.org/incident_notes/IN-98.03.html"&gt;Here&lt;/A&gt; is a random CERT account of someone who collected passwords.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;CERT claims some passwords where sniffed, but I have no idea how they would know that.&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Finally, &lt;A href="http://zdnet.com.com/2100-1106-871061.html"&gt;here&lt;/A&gt; is a random article about E-Bay.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;There isn't any evidence that e-bay customers had their passwords sniffed, though.&amp;nbsp;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Although password sniffing is rare, it is still something that people should worry about.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Common sense dictates that we shouldn&amp;#8217;t be storing or sending plaintext passwords.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Although your chances of getting struck by lightening are pretty low, you should still get out of the water when a thunder-storm arrives.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=86868" width="1" height="1"&gt;</description></item><item><title>Apps that email passwords</title><link>http://blogs.msdn.com/stephen_mccloskey/archive/2004/02/27/81375.aspx</link><pubDate>Sat, 28 Feb 2004 02:34:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:81375</guid><dc:creator>Stephen_McCloskey</dc:creator><slash:comments>10</slash:comments><comments>http://blogs.msdn.com/stephen_mccloskey/comments/81375.aspx</comments><wfw:commentRss>http://blogs.msdn.com/stephen_mccloskey/commentrss.aspx?PostID=81375</wfw:commentRss><description>&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Why does the ASP.net administrative site send your plaintext password to you in email whenever you change it?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This strikes me as a bad idea.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;For that matter, why doesn&amp;#8217;t the ASP.net site use https on the page that allows you to change your password?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Your password is not very secure if the darn thing is floating around the internet and in random mail boxes - in plaintext.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Jeez!&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Packets can be sniffed and most mail boxes can be read by an administrator (or whoever has access to the backup).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/P&gt;
&lt;P class=MsoNormal style="MARGIN: 0in 0in 0pt"&gt;Passwords are like an infectious disease.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;You want to handle them carefully and avoid them whenever possible.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;They are an essential part of modern applications, but many developers don&amp;#8217;t respect how easily they can be compromised if mishandled.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Fear the evil password! Don&amp;#8217;t ever write an app that tosses them around in plaintext! &lt;/P&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=81375" width="1" height="1"&gt;</description></item></channel></rss>